Privacy Policy (GDPR)
Data controller:
Tomáš Huml
Company ID: 23925230
Address: Dukelská 418, 76901 Holešov
E-mail: totalwebcare@seznam.cz
Phone: +420 731 890 372
Web: www.ultimweb.cz
Purpose: protection of the personal data of the website’s visitors and customers.
1. General provisions
The controller of personal data is Tomáš Huml (hereinafter the “controller”). The controller’s contact details are given above.
Personal data means any information about an identified or identifiable natural person (e.g. name, company ID, address, e-mail, IP address, cookies).
2. Sources and categories of processed data
The controller processes data that the customer or visitor has provided (e.g. when ordering a service, registering or getting in touch through the form).
The data processed are in particular: identification data (first name, surname), contact details (e-mail, phone, address) and data necessary for the performance of the contract.
3. Legal basis and purpose of processing
- Performance of the contract between the customer and the controller (Art. 6(1)(b) GDPR).
- The controller’s legitimate interest in marketing (sending commercial communications and newsletters) (Art. 6(1)(f) GDPR).
- The customer’s consent to processing for marketing purposes (Art. 6(1)(a) GDPR).
Purpose of processing: handling the order, providing the service, contacting the customer, marketing and sending newsletters.
4. Retention period
Personal data are kept for as long as necessary to perform the contract and to exercise the rights arising from it. Once the retention period expires, the data are securely deleted.
5. Recipients of personal data (subcontractors)
Personal data may be disclosed to suppliers of services necessary for the performance of the contract, to providers of technical services (hosting, cloud) and to marketing agencies. Data may also be processed outside the EU where this is necessary for providing the services.
6. Rights of the data subject
- Access to your personal data (Art. 15 GDPR).
- Rectification of personal data (Art. 16 GDPR).
- Erasure of personal data (the “right to be forgotten”) (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Objection to processing (Art. 21 GDPR).
- Data portability (Art. 20 GDPR).
- Withdrawal of consent to data processing, in writing or electronically.
You may also lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
7. Security of personal data
The controller has adopted appropriate technical and organisational measures to protect the data. Only authorised persons have access to personal data. Data storage is protected by security measures (passwords, encryption, physical protection).
8. Final provisions
By placing an order or using a service, the customer confirms that they have read this policy and agree to it. The controller may change this policy at any time – the new version will be published on the website.
This policy takes effect on 5 November 2025.